Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.5
CVE-2026-71543: OpenBao policies let attacker raise privileges via wildcards
CVE-2026-71543 · published 8 days ago
Summary
OpenBao lets you create policies that include placeholders, such as a user name, which are filled in when the policy is used. If an attacker can choose the placeholder value and include characters like *, + or /, they can broaden the policy to gain access to data or certificates they shouldn’t have. Restrict the characters allowed in template inputs or avoid using wildcards in these policies to prevent the escalation.
What to do
- Update github.com openbao to version 0.0.0-20260710001938-2d4ebafec5c5.
- Update openbao github.com/openbao/openbao to version 0.0.0-20260710001938-2d4ebafec5c5.
- Update openbao to version 2.6.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | github.com | openbao |
< 0.0.0-20260710001938-2d4ebafec5c5 >= 0.1.0, <= 1.1.5 Fix: upgrade to 0.0.0-20260710001938-2d4ebafec5c5
|
| Go | openbao | github.com/openbao/openbao |
< 0.0.0-20260710001938-2d4ebafec5c5 >= 0.1.0, <= 1.1.5 Fix: upgrade to 0.0.0-20260710001938-2d4ebafec5c5
|
| – | openbao | openbao | <2.6.0 |
| Bitnami | – | openbao |
< 2.6.0 Fix: upgrade to 2.6.0
|
Original advisory text
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated policies, asterisks, plus signs, and slashes could alter path matching. In PKI allowed_uri_sans_template and allowed_domains policies, an asterisk could broaden certificate issuance to unauthorized domains. In SSH allowed_users and allowed_domains policies, a comma could add unauthorized principals. Exploitation requires a deployment to use templated policy data that users can freely modify; templates based on the randomly generated identity.entity.id value are not affected. This could allow privilege escalation, unauthorized access, and unauthorized certificate issuance. This issue is fixed in version 2.6.0.
References
- https://github.com/openbao/openbao/security/advisories/GHSA-59w7-v8rr-pr4p
- https://github.com/openbao/openbao/commit/2d4ebafec5c524408b3d4ac1198df909cb7ac8...
- https://github.com/openbao/openbao/releases/tag/v2.6.0
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71543... Vendor Advisory
- https://github.com/advisories/GHSA-59w7-v8rr-pr4p
- https://github.com/openbao/openbao/commit/e516ce508e1481504cadbfbf62052364339093...
- https://nvd.nist.gov/vuln/detail/CVE-2026-71543 Vendor Advisory
- https://github.com/openbao/openbao/pull/3401
- https://github.com/openbao/openbao/pull/3473
- https://github.com/hashicorp/vault/blob/main/CHANGELOG.md#201
- https://github.com/openbao/openbao Product
Severity
7.5
High
CVSS 4.0: 7.5 (NVD)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published21 Sep 2026
Updated29 Sep 2026
First seen21 Sep 2026
Sources
CVE-2026-71543 · NVD
CVE-2026-71543 · MITRE
CVE-2026-71543 · OSV
GHSA-59w7-v8rr-pr4p · GHSA
GHSA-59w7-v8rr-pr4p · OSV
BIT-openbao-2026-71543 · OSV
Track software like this
Free during beta